Endpoints & authentication
Gateways
Section titled “Gateways”| Region | Endpoint |
|---|---|
| Europe | eu.tpp.io:8888 |
| Americas | us.tpp.io:8888 |
| Asia Pacific | asia.tpp.io:8888 |
Connect to the region closest to your infrastructure. The gateway only decides where your connection enters the network; the exit IP is chosen by your targeting, and the full pool is reachable from every region.
Protocols
Section titled “Protocols”Every gateway speaks three protocols on TCP port 8888, auto-detected (port 1080 serves exactly the same):
- HTTP CONNECT - what
curl -x http://...and most HTTP clients use. HTTPS traffic tunnels through this. - Plain HTTP forwarding - absolute-form requests (
GET http://host/path) for plain-HTTP targets. - SOCKS5 - with username/password authentication. Works for any TCP protocol.
HTTP/3
Section titled “HTTP/3”The same gateways accept HTTP/3 CONNECT on UDP port 1080 only, over QUIC with TLS. One QUIC connection carries many concurrent tunnels with no head-of-line blocking between them, and a resumed connection costs no extra round trip - worth it if you open many short-lived connections, or from a lossy or high-latency network.
Send a CONNECT request whose :authority is your target host:port, with your credential in a Proxy-Authorization: Basic header. Authentication and targeting are identical to the TCP protocols, and every option in targeting works the same way.
Client support is the catch. HTTP/3 to a proxy is much less widely implemented than HTTP/3 to a website, and curl does not support it at all - --http3 applies to the origin connection, and there is no proxy equivalent. Today this needs a client built directly on an HTTP/3 library, such as h3 with quinn in Rust, or aioquic in Python. If your client cannot do it, use the TCP port - there is no loss of function, only of the multiplexing.
Two other limits are worth knowing. Only CONNECT is accepted over HTTP/3 - plain HTTP forwarding needs the TCP port. And QUIC ends at the gateway: the exit leg is always TCP, so this does not proxy UDP traffic to your target.
Target hosts can be domains, IPv4 or IPv6 addresses. Domains are resolved from the exit’s network vantage, so geo-fenced content resolves the way it would for that household - prefer socks5h:// over socks5:// in clients that distinguish them, so your machine doesn’t resolve the name locally.
Authentication
Section titled “Authentication”Credentials go in the proxy username and password:
curl -x http://USER:PASS@eu.tpp.io:8888 https://example.comThe username is your proxy user, optionally followed by targeting options (USER-cc-de-session-abc). The password is always just your proxy password.
Proxy usernames are 3-64 characters of letters, digits, _ or . - no hyphens, since the hyphen separates targeting options. Credential changes made in the dashboard or API reach the gateways within a few seconds.
A failed authentication (HTTP 407, or a SOCKS5 auth failure) means one of:
- wrong username or password
- a malformed or unknown targeting option - options are validated, never silently ignored
- your bandwidth balance is exhausted
- your account is disabled
Metering
Section titled “Metering”Usage is metered in bytes, both directions, against your prepaid balance. When the balance runs out, authentication starts failing - connections are never cut mid-transfer. Check your balance on the dashboard or via GET /v1/me.